Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-182207.8 HIG21.9%
——7An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.
A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().
Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.
Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).41dCVE-2026-660045.3 MED21.9%
——7BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like '../../.bashrc' to overwrite sensitive files and achieve persistent code execution.40dCVE-2025-12648—21.9%
——7——CVE-2024-12815—21.9%
——7——CVE-2026-308039.1 CRI21.9%
——7Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.63dCVE-2024-9421—21.9%
——7——CVE-2022-45478—21.9%
——7——CVE-2024-10076—21.9%
——7——CVE-2023-0251—21.9%
——7——CVE-2025-6345—21.9%
——7——CVE-2017-18840—21.9%
——7——CVE-2026-2592—21.9%
——7——CVE-2022-35111—21.9%
——7——CVE-2026-49057—21.9%
——7——CVE-2025-25469—21.9%
——7——CVE-2022-41286—21.9%
——7——CVE-2025-48244—21.9%
——7——CVE-2025-151156.5 MED21.9%
——7Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification.50dCVE-2025-25634—21.9%
——7——CVE-2025-93149.8 CRI21.9%
——7The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component5dCVE-2025-30907—21.9%
——7——CVE-2023-37334—21.9%
——7——CVE-2024-47135—21.9%
——7——CVE-2022-36611—21.9%
——7——CVE-2023-37337—21.9%
——7——CVE-2024-8033—21.9%
——7——CVE-2025-30203—21.9%
——7——CVE-2025-30855—21.9%
——7——CVE-2024-43802—21.9%
——7——CVE-2025-1985—21.9%
——7——CVE-2026-35597—21.9%
——7——CVE-2025-47525—21.9%
——7——CVE-2025-22315—21.9%
——7——CVE-2026-41571—21.9%
——7——CVE-2024-10269—21.9%
——7——CVE-2023-38699—21.9%
——7——CVE-2025-10002—21.9%
——7——CVE-2023-26592—21.9%
——7——CVE-2025-49854—21.9%
——7——CVE-2026-726536.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.7d